test: add 3xx-redirect failure and no-credential-header/URL checks
CI / Run tests (pull_request) Successful in 16s
CI / Secret scan (gitleaks) (pull_request) Failing after 13s

Extends the newsletter suite with two boundary cases: redirects (301/302/307/
308) must be treated as failures with the user-safe error, and the POST must
carry no credential of any kind — no api-key/auth-token/cookie headers, and no
token/secret in the body or URL.
This commit is contained in:
implementer
2026-08-26 11:31:54 +00:00
parent 86aa3afbbf
commit 32c81d8b91
+25
View File
@@ -197,7 +197,20 @@ test("submitNewsletterSignup POSTs the email with no Authorization header or cre
!Object.keys(init.headers).some((h) => h.toLowerCase() === "authorization"), !Object.keys(init.headers).some((h) => h.toLowerCase() === "authorization"),
"request must not carry an Authorization header", "request must not carry an Authorization header",
); );
// No credential of any kind: no api-key/auth-token headers, and no token or
// secret in the body or URL either.
for (const header of Object.keys(init.headers)) {
const lower = header.toLowerCase();
assert.ok(
!["x-api-key", "x-auth-token", "x-access-token", "cookie"].includes(lower),
`request must not carry credential header ${header}`,
);
}
assert.deepEqual(JSON.parse(init.body), { email: "ada@example.com" }); assert.deepEqual(JSON.parse(init.body), { email: "ada@example.com" });
assert.ok(!url.includes("token"));
assert.ok(!url.includes("key"));
assert.ok(!url.includes("secret"));
assert.ok(!JSON.stringify(init.body).includes("token"));
}); });
test("submitNewsletterSignup defaults to the configured endpoint", async () => { test("submitNewsletterSignup defaults to the configured endpoint", async () => {
@@ -285,6 +298,18 @@ test("a network failure shows the same user-safe error", async () => {
assert.equal(result.message, NEWSLETTER_ERROR_MESSAGE); assert.equal(result.message, NEWSLETTER_ERROR_MESSAGE);
}); });
test("a redirect (3xx) is treated as a failure with the same user-safe error", async () => {
for (const status of [301, 302, 307, 308]) {
const fetchImpl = fakeFetch({ ok: false, status, text: async () => "redirecting" });
const result = await submitNewsletterSignup("ada@example.com", {
endpoint: "https://api.example.com/newsletter",
fetchImpl,
});
assert.equal(result.ok, false);
assert.equal(result.message, NEWSLETTER_ERROR_MESSAGE);
}
});
test("an invalid email fails fast with a user-safe error and no network call", async () => { test("an invalid email fails fast with a user-safe error and no network call", async () => {
const fetchImpl = fakeFetch({ ok: true }); const fetchImpl = fakeFetch({ ok: true });
const result = await submitNewsletterSignup("not-an-email", { const result = await submitNewsletterSignup("not-an-email", {